Global CLAUDE.md — Security Gatekeeper & Standards
> Place this at ~/.claude/CLAUDE.md
> It applies to EVERY project you work on.
> Based on Claude Code Mastery Guides V1-V5 by TheDecipherist
---
## Identity
- GitHub: **YourUsername
docker-compose.example.yml docker-compose.yml)
docker compose up
docker compose up --build
```
## Key Conventions
1. **Token security** — Encrypted tokens are never logged, printed, or included in error messages. AES-256-GCM in `token_vault.py
such as Anthropic's official directory,
is additive and never replaces the entry here.
## Security
When documenting examples, obfuscate sensitive info:
- Workspace IDs: use `1111111111111111` not real IDs
- URLs
tests with Claude and MCPControl
## Running with HTTPS/TLS
MCPControl supports HTTPS for secure SSE connections (mandatory per MCP spec for production):
- `node build/index.js --sse --https --cert /path/to/cert.pem --key /path/to/key.pem`
- Default
authorize the caller separately from receiver ownership, and never use instance master as a security or access-control boundary.
## Skills
| Skill | Purpose | Path |
|-------|---------|------|
| `unity-vrc-udon-sharp` | UdonSharp coding, networking
strategy
- Each sub-task should have its own commit (as per Task splitting section)
## Security
- **Secrets Detection**: GitGuardian runs in CI to detect leaked secrets
- **Secrets Retrieval**: Always use `Configuration.getConfig
file edits) belong on a cheap model (Haiku/Sonnet); reserve Opus/Fable for architecture, debugging, and security reasoning.
## Gotchas (what you can't infer from the code)
- **After pulling changes that touch
unit # Run unit tests only
make test-integration # Run integration tests only
make test-security # Run security tests only
make test-config # Run configuration tests
make test-fast # Fast
never need `SPOTIFY_SP_DC`); never edit
or weaken a gate, `.github/`, release, or security config; make the smallest correct
change; and the **evidence standard** is the bar for "done
A file Claude Code reads at the start of every session. It holds the commands, conventions and warnings the agent needs for this project.
Where does it go?
At the repository root. Claude Code also reads CLAUDE.md files in subdirectories when it works there.
What should it contain?
Build and test commands, the project's layout, conventions that aren't obvious from the code, and mistakes to avoid. Short files tend to work better than long ones.
CLAUDE.md or AGENTS.md?
Claude Code reads CLAUDE.md; most other agents read AGENTS.md. Many projects keep one and point the other at it.